CVE-2026-42171: High severity Nullsoft NSIS vulnerability
NSIS (Nullsoft Scriptable Install System) 3.06.1 before 3.12 sometimes uses the Low IL temp directory when executing as SYSTEM, allowing local attackers to gain privileges (if they can cause myGetTempFileName to return 0, as shown in the references).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42171?
CVE-2026-42171 is a privilege escalation vulnerability with a significant impact if successfully exploited.
How do I fix CVE-2026-42171?
To fix CVE-2026-42171, update NSIS from version 3.06.1 to the latest version 3.12 or later.
What type of attacks can exploit CVE-2026-42171?
CVE-2026-42171 can be exploited by local attackers who can manipulate the my_GetTempFileName function.
Who is affected by CVE-2026-42171?
Users of NSIS versions between 3.06.1 and 3.11 are affected by CVE-2026-42171.
What is NSIS in relation to CVE-2026-42171?
NSIS, or Nullsoft Scriptable Install System, is an application used for creating Windows installers that is affected by CVE-2026-42171.